Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 8 additions & 7 deletions .github/workflows/check-types.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,6 @@ on:
branches:
- main
pull_request:
branches:
- main

jobs:
type-check:
Expand All @@ -17,25 +15,28 @@ jobs:
with:
submodules: recursive

- name: Set up Python 3.9
- name: Set up Python 3.12
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7
with:
python-version: 3.9
python-version: "3.12"

- name: Install uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
version: "0.12.24"
enable-cache: true
cache-dependency-glob: "uv.lock"

- name: Install the project
run: uv sync --all-extras --dev
run: uv sync --locked --all-extras --dev

- name: Install workspace packages
run: uv pip install -e livekit-protocol -e livekit-api -e livekit-rtc

- name: Download ffi
run: uv run python livekit-rtc/rust-sdks/download_ffi.py --output .venv/lib/python3.9/site-packages/livekit/rtc/resources
run: uv run python livekit-rtc/rust-sdks/download_ffi.py --output livekit-rtc/livekit/rtc/resources

- name: Check Types
run: uv run mypy livekit-protocol livekit-api livekit-rtc
run: |
uv run mypy livekit-protocol livekit-api livekit-rtc
uv run mypy --python-version 3.9 livekit-protocol/livekit livekit-api/livekit livekit-rtc/livekit
5 changes: 3 additions & 2 deletions .github/workflows/ruff.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,16 +7,17 @@ jobs:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7
with:
python-version: "3.9"
python-version: "3.12"

- name: Install uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
version: "0.12.24"
enable-cache: true
cache-dependency-glob: "uv.lock"

- name: Install the project
run: uv sync --all-extras --dev
run: uv sync --locked --all-extras --dev

# Use the ruff version pinned in uv.lock rather than uvx's latest release,
# so lint results only change when the lockfile is intentionally updated.
Expand Down
8 changes: 8 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -404,6 +404,14 @@ Software encoders (libvpx for VP8/VP9, libaom for AV1, OpenH264 for H264) are us

Please join us on [Slack](https://livekit.io/join-slack) to get help from our devs / community members. We welcome your contributions(PRs) and details can be discussed there.

### Development environment

The published SDKs support Python 3.9 and later. Development and release tooling
requires Python 3.10 or later so that patched versions of its dependencies can be
installed. For example, run `uv sync --locked --dev --python 3.12` from the
repository root. A Python 3.9 runtime environment can use
`uv sync --locked --no-dev --python 3.9`.

<!--BEGIN_REPO_NAV-->
<br/><table>
<thead><tr><th colspan="2">LiveKit Ecosystem</th></tr></thead>
Expand Down
18 changes: 16 additions & 2 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,20 @@ description = "LiveKit Python SDKs monorepo"
requires-python = ">=3.9"
dependencies = ["livekit", "livekit-api", "livekit-protocol"]

[tool.uv]
# Security floors for transitive development and release dependencies.
constraint-dependencies = [
"cryptography>=50.0.0",
"filelock>=3.20.3",
"pillow>=12.3.0",
"pygments>=2.20.0",
"urllib3>=2.8.0",
]
Comment on lines +8 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟨 Release builds bypass patched dependency floors

When release jobs build wheels, constraint-dependencies does not constrain their pip and pipx installs. RTC builds and isolated build dependencies can still select older affected versions.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.


[tool.uv.dependency-groups]
# Patched tooling requires Python 3.10; published SDKs still support Python 3.9.
dev = { requires-python = ">=3.10" }

[tool.uv.workspace]
members = ["livekit-rtc", "livekit-api", "livekit-protocol"]

Expand All @@ -21,10 +35,10 @@ dev = [
"types-aiofiles>=24",
"ipython>=8.0.0",
# Testing
"pytest>=8.3.4",
"pytest>=9.0.3",
"pytest-asyncio>=0.24.0",
# Build and packaging
"requests",
"requests>=2.33.0",
"wheel",
"twine",
"auditwheel; sys_platform == 'linux'",
Expand Down
Loading
Loading